{"id":15552,"date":"2026-01-31T09:56:57","date_gmt":"2026-01-31T16:56:57","guid":{"rendered":"https:\/\/jasonsblog.ddns.net\/?p=15552"},"modified":"2026-01-31T09:56:57","modified_gmt":"2026-01-31T16:56:57","slug":"systemd-daddy-quits-microsoft-to-prove-linux-can-be-trusted","status":"publish","type":"post","link":"https:\/\/jasonsblog.ddns.net\/index.php\/2026\/01\/31\/systemd-daddy-quits-microsoft-to-prove-linux-can-be-trusted\/","title":{"rendered":"Systemd Daddy Quits Microsoft To Prove Linux Can Be Trusted"},"content":{"rendered":"\n<p>Immutable distributions are all the rage these days, so is this a play for an <a href=\"https:\/\/www.zdnet.com\/article\/what-is-immutable-linux-heres-why-youd-run-an-immutable-linux-distro\/\" target=\"_blank\" rel=\"noreferrer noopener\">immutable distribution<\/a>? Or perhaps a server implementation with more containerization for Docker, Podman applications? The most famous form of an immutable distribution is Google&#8217;s Chrome OS, with two boot channels for firmware and the OS, which is hashed to verify that it hasn&#8217;t been tampered with. If there is a failure, it resorts to the other boot channel, then updates the bad one in the background. And why it does so well with updates, as it updates the unused boot channel to use on next boot, if there is an issue it reverts back, or if successful, mirrors the update. And the kernel is made read only on successful boot so it can&#8217;t be tampered with. Now Linux immutable distributions do things a little different with making the core system read only, only applying updates on reboot with easy fallback if issues, and then containerizing applications in Flatpak, Snap or AppImages. The containerizing of applications I have a problem with, so I&#8217;d never use one of these though I did play around with NixOS for a spell which had compelling use cases for corporate operations and uniformity with easy rollouts of system configurations, though the project is run by <a href=\"https:\/\/jasonsblog.ddns.net\/index.php\/2024\/11\/19\/nixos-commits-a-purge-of-nazi-contributors-forces-abdication-of-founder\/\" target=\"_blank\" rel=\"noreferrer noopener\">far left liberals who ran off conservatives<\/a>, so I wouldn&#8217;t use it today. <\/p>\n\n\n\n<p><a href=\"https:\/\/www.theregister.com\/2026\/01\/29\/lennart_poettering_quits_microsoft\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.theregister.com\/2026\/01\/29\/lennart_poettering_quits_microsoft\/<\/a><\/p>\n\n\n<div class=\"wp-block-ub-divider ub_divider ub-divider-orientation-horizontal\" id=\"ub_divider_b842d5d5-6305-4e99-b00a-1f801a2b80cd\"><div class=\"ub_divider_wrapper\" style=\"position: relative; margin-bottom: 2px; width: 100%; height: 2px; \" data-divider-alignment=\"center\"><div class=\"ub_divider_line\" style=\"border-top: 2px solid #ccc; margin-top: 2px; \"><\/div><\/div><\/div>\n\n\n<h5 class=\"wp-block-heading\">Lennart Poettering&#8217;s Amutable aims to bring &#8216;cryptographically verifiable integrity&#8217; to the other OS<\/h5>\n\n\n\n<figure class=\"wp-block-image alignright size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"329\" height=\"304\" src=\"https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/01\/image-54.png\" alt=\"\" class=\"wp-image-15553\" srcset=\"https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/01\/image-54.png 329w, https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/01\/image-54-300x277.png 300w\" sizes=\"auto, (max-width: 329px) 100vw, 329px\" \/><\/figure>\n\n\n\n<p>Linux celeb Lennart Poettering has left Microsoft and co-founded a new company, Amutable, with Chris K\u00fchl and Christian Brauner.<\/p>\n\n\n\n<p>Poettering is best known for systemd. After a lengthy stint at Red Hat, he <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2022\/07\/07\/lennart_poettering_red_hat_microsoft\/\" rel=\"noreferrer noopener\">joined Microsoft in 2022<\/a>. K\u00fchl was a Microsoft employee until last year, and Brauner, who also joined Microsoft in 2022, left this month.<\/p>\n\n\n\n<p>The trio are leading lights in the Linux and open source world. Brauner <a target=\"_blank\" rel=\"noreferrer noopener\" href=\"https:\/\/mastodon.social\/@brauner\/115968807569462508\">posted<\/a> on Mastodon: &#8220;My role in upstream maintenance for the Linux kernel will continue as it always has.&#8221;<\/p>\n\n\n\n<p>Poettering will similarly remain deeply involved in the systemd ecosystem.<\/p>\n\n\n\n<p>According to the company&#8217;s <a target=\"_blank\" rel=\"noreferrer noopener\" href=\"https:\/\/amutable.com\/blog\/introducing-amutable\">website<\/a>, Amutable focuses on &#8220;determinism and verifiable integrity&#8221; in Linux systems.<\/p>\n\n\n\n<p>In its announcement, the company wrote: &#8220;Amutable&#8217;s mission is to deliver verifiable integrity to Linux workloads everywhere. We look forward to working towards this goal with the broader Linux community.&#8221;<\/p>\n\n\n\n<p>Systemd and Poettering have attracted their fair share of controversy over the years among parts of the Linux community. Like it or loathe it, systemd can be found in most mainstream Linux distributions. At the risk of triggering a slew of angry comments, it can best be described as software that runs first, then starts other required services and applications.<\/p>\n\n\n\n<p>Poettering&#8217;s role as chief engineer in Amutable, therefore, makes sense. The Berlin-based company&#8217;s goal is to build &#8220;cryptographically verifiable integrity into Linux systems. Every system starts in a verified state and stays trusted over time.&#8221;<\/p>\n\n\n\n<p>It is unclear why Poettering decided to leave Microsoft. We asked the company to comment but have not received a response. Other than the announcement of <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2025\/11\/20\/rc_systemd_259\/\" rel=\"noreferrer noopener\">systemd 259<\/a> in December, <a target=\"_blank\" rel=\"noreferrer noopener\" href=\"https:\/\/0pointer.de\/blog\/\">Poettering&#8217;s<\/a> blog has been silent on the matter, aside from the announcement of Amutable this week.<\/p>\n\n\n\n<p>In its first post, the Amutable team wrote: &#8220;Over the coming months, we&#8217;ll be pouring foundations for verification and building robust capabilities on top.&#8221;<\/p>\n\n\n\n<p>It will be interesting to see what form this takes. In addition to Poettering, the lead developer of systemd, Amutable&#8217;s team includes contributors and maintainers for projects such as Linux, Kubernetes, and containerd. Its members are also very familiar with the likes of Debian, Fedora, SUSE, and Ubuntu.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Immutable distributions are all the rage these days, so is this a play for an immutable distribution? Or perhaps a server implementation with more containerization for Docker, Podman applications? The most famous form of an immutable distribution is Google&#8217;s Chrome OS, with two boot channels for firmware and the OS, which is hashed to verify [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-15552","post","type-post","status-publish","format-standard","hentry","category-tech"],"blocksy_meta":[],"featured_image_src":null,"author_info":{"display_name":"Jason","author_link":"https:\/\/jasonsblog.ddns.net\/index.php\/author\/jturning\/"},"_links":{"self":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/15552","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/comments?post=15552"}],"version-history":[{"count":1,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/15552\/revisions"}],"predecessor-version":[{"id":15554,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/15552\/revisions\/15554"}],"wp:attachment":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/media?parent=15552"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/categories?post=15552"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/tags?post=15552"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}